Malicious code in mazemap (npm)
--- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (751317dcad79cec866b8dc69cd60b39e3be8e1bcc45746039835b04ce32445b0) package.json declares its only dependency `ltidisafe` as a direct HTTPS tarball URL (`https://ltidi.storage.googleapis.com/depenconf/ltidisafe-3.0.2.tgz`) hosted on a generic Google Cloud Storage bucket rather than resolved from the npm registry. On `npm install mazemap`, npm fetches and installs that arbitrary tarball, executing any lifecycle scripts (preinstall/install/postinstall) it contains — the tarball is bucket-owner-mutable and not subject to registry vetting. The package itself is a hollow lure: `index.js` is a 35-byte `module.exports = {};`, with no description, no author, ISC default license, and version `99.9.1` — a recognized dependency-confusion technique for overriding an internal package of the same name via a higher public version. The bucket path segment is literally `depenconf`. The combination of hollow main, inflated version, anonymous GCS-hosted dependency, and name collision with a real product (MazeMap) is a dependency-confusion / smuggling shape whose only on-install effect is to pull and execute attacker-controlled code from a non-registry source. ## Source: ghsa-malware (b2544226891e60a2b6f33b0aacf3e4669fe4ce13220f01bd40a84c8657fe0518) Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.
AI Analysis
Technical Summary
The mazemap package (version 99.9.1) on npm declares a single dependency 'ltidisafe' via a direct HTTPS tarball URL hosted on a Google Cloud Storage bucket, bypassing npm registry vetting. This bucket is mutable by the attacker and contains arbitrary code executed during npm install lifecycle scripts. The package uses a dependency confusion technique by having a hollow main module and an inflated version number to override an internal package of the same name. The installation of this package results in execution of attacker-controlled code, potentially fully compromising the host system.
Potential Impact
Installing mazemap version 99.9.1 results in execution of attacker-controlled code from a non-registry source, leading to full compromise of the affected system. All secrets and keys stored on the compromised system should be considered exposed and require immediate rotation. Removal of the package alone does not guarantee eradication of the malicious software installed.
Mitigation Recommendations
Remove the mazemap package version 99.9.1 immediately from all affected systems. Rotate all secrets and keys that were stored or accessible on the compromised systems using a separate, trusted environment. Because the package executes arbitrary code during installation, assume full system compromise and conduct a thorough incident response. There is no official patch or fix; remediation requires removal and secret rotation.
Malicious code in mazemap (npm)
Description
--- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (751317dcad79cec866b8dc69cd60b39e3be8e1bcc45746039835b04ce32445b0) package.json declares its only dependency `ltidisafe` as a direct HTTPS tarball URL (`https://ltidi.storage.googleapis.com/depenconf/ltidisafe-3.0.2.tgz`) hosted on a generic Google Cloud Storage bucket rather than resolved from the npm registry. On `npm install mazemap`, npm fetches and installs that arbitrary tarball, executing any lifecycle scripts (preinstall/install/postinstall) it contains — the tarball is bucket-owner-mutable and not subject to registry vetting. The package itself is a hollow lure: `index.js` is a 35-byte `module.exports = {};`, with no description, no author, ISC default license, and version `99.9.1` — a recognized dependency-confusion technique for overriding an internal package of the same name via a higher public version. The bucket path segment is literally `depenconf`. The combination of hollow main, inflated version, anonymous GCS-hosted dependency, and name collision with a real product (MazeMap) is a dependency-confusion / smuggling shape whose only on-install effect is to pull and execute attacker-controlled code from a non-registry source. ## Source: ghsa-malware (b2544226891e60a2b6f33b0aacf3e4669fe4ce13220f01bd40a84c8657fe0518) Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The mazemap package (version 99.9.1) on npm declares a single dependency 'ltidisafe' via a direct HTTPS tarball URL hosted on a Google Cloud Storage bucket, bypassing npm registry vetting. This bucket is mutable by the attacker and contains arbitrary code executed during npm install lifecycle scripts. The package uses a dependency confusion technique by having a hollow main module and an inflated version number to override an internal package of the same name. The installation of this package results in execution of attacker-controlled code, potentially fully compromising the host system.
Potential Impact
Installing mazemap version 99.9.1 results in execution of attacker-controlled code from a non-registry source, leading to full compromise of the affected system. All secrets and keys stored on the compromised system should be considered exposed and require immediate rotation. Removal of the package alone does not guarantee eradication of the malicious software installed.
Mitigation Recommendations
Remove the mazemap package version 99.9.1 immediately from all affected systems. Rotate all secrets and keys that were stored or accessible on the compromised systems using a separate, trusted environment. Because the package executes arbitrary code during installation, assume full system compromise and conduct a thorough incident response. There is no official patch or fix; remediation requires removal and secret rotation.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- MAL-2026-5448
- Osv Schema Version
- 1.7.4
- Aliases
- ["GHSA-xc8q-h68h-r6r9"]
- Ecosystems
- ["npm"]
- Database Specific Severity
- null
- Cvss Version
- null
Threat ID: 6a520ed368715ace439019a2
Added to database: 07/11/2026, 09:37:23 UTC
Last enriched: 07/11/2026, 10:00:23 UTC
Last updated: 07/29/2026, 10:44:47 UTC
Views: 14
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.